Better late than never, Dell fixes 12-year-old vulnerability affecting hundreds of millions of PCs

Dell Xps 13 9300 Lid
Dell Xps 13 9300 Lid (Image credit: Daniel Rubino/Windows Central)

What you need to know

  • A 12-year-old vulnerability was discovered in Dell computers and flagged up to the company.
  • It's estimated that hundreds of millions of devices have the vulnerability.
  • Dell has released a security update to address the vulnerability.

The flaws in the firmware update are all assigned one Common Vulnerabilities and Exposures (CVE) number, but SentinelLabs breaks them down into five flaws:

  • CVE-2021-21551: Local Elevation Of Privileges #1 – Memory corruption
  • CVE-2021-21551: Local Elevation Of Privileges #2 – Memory corruption
  • CVE-2021-21551: Local Elevation Of Privileges #3 – Lack of input validation
  • CVE-2021-21551: Local Elevation Of Privileges #4 – Lack of input validation
  • CVE-2021-21551: Denial Of Service – Code logic issue

SentinelLabs already has a proof of concept to demonstrate how these issues can affect PCs but is withholding sharing it until June 1, 2021 to give people a chance to update.

The report from SentinelLabs explains the potential impact of the vulnerabilities:

The high severity flaws could allow any user on the computer, even without privileges, to escalate their privileges and run code in kernel mode. Among the obvious abuses of such vulnerabilities are that they could be used to bypass security products.

The report adds that an attacker with access to an organization's network can also manage to execute code to gain local elevation of privilege.

Dell released a patch for the vulnerabilities and explains them in great detail in a support document.

SentinelLabs states that it hasn't seen any indication that the vulnerabilities have been exploited in the wild, but warns that "with hundreds of millions of enterprises and users currently vulnerable, it is inevitable that attackers will seek out those that do not take the appropriate action."

Sean Endicott
News Writer and apps editor

Sean Endicott is a news writer and apps editor for Windows Central with 11+ years of experience. A Nottingham Trent journalism graduate, Sean has covered the industry’s arc from the Lumia era to the launch of Windows 11 and generative AI. Having started at Thrifter, he uses his expertise in price tracking to help readers find genuine hardware value.

Beyond tech news, Sean is a UK sports media pioneer. In 2017, he became one of the first to stream via smartphone and is an expert in AP Capture systems. A tech-forward coach, he was named 2024 BAFA Youth Coach of the Year. He is focused on using technology—from AI to Clipchamp—to gain a practical edge.